chore(deps): Update npm-deps - #617
Conversation
|
This was written agentically; verify its assertions and edit accordingly: Adversarial cross-review — Codex
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
56e2bc6 to
b4dee33
Compare
76ea4f5 to
7fa80b2
Compare
7fa80b2 to
9d77e18
Compare
This PR contains the following updates:
15.5.0→15.5.11.29.0→1.30.01.0.2→1.0.32.40.0→2.41.28.6.0→8.6.16.1.200→6.2.108Release Notes
APIDevTools/json-schema-ref-parser (@apidevtools/json-schema-ref-parser)
v15.5.1Compare Source
Bug Fixes
modelcontextprotocol/typescript-sdk (@modelcontextprotocol/sdk)
v1.30.0Compare Source
Brooooooklyn/canvas (@napi-rs/canvas)
v1.0.3Compare Source
Bug Fixes
Features
Redocly/redocly-cli (@redocly/cli)
v2.41.2Compare Source
Patch Changes
Updated js-yaml from
5.2.1to5.2.2to resolve a vulnerability in YAML parsing.Added support for the Arazzo spec-compliant workflow reference form
$sourceDescriptions.<name>.<workflowId>independsOn, stepworkflowId, and success/failure actionworkflowId.Unresolvable workflow references fail only the affected workflow with a clear error message, and no longer abort the whole run or pass unnoticed.
Updated @redocly/openapi-core to v2.41.2.
Updated @redocly/respect-core to v2.41.2.
v2.41.1Compare Source
Patch Changes
driftcommand'sschema-consistencyrule reported false-positive findings foroneOfschemas with adiscriminator.Payloads are validated only against the branch selected by the discriminator value instead of every
oneOfbranch.Schemas whose discriminator does not meet Ajv's structural requirements keep the previous behavior.
driftcommand's built-in undocumented-header ignore list withx-amz-,x-amzn-andx-github-prefixes, and thex-hub-signature/x-hub-signature-256webhook signature headers.v2.41.0Compare Source
Minor Changes
security-scopes-definedthat requires every scope used in a security requirement to be defined in the corresponding OAuth2 security scheme.The rule supports OpenAPI 2.0/3.x and AsyncAPI 2.6/3.0, suggests the closest defined scope for typos, and has an opt-in
requireScopesoption that requires OAuth2 security requirements to list at least one scope.Patch Changes
respectwhere the execution of parent workflow's steps didn't halt after a step that referenced another workflow had failed.cursorAI provider of thegenerate-speccommand sent only the instructions to the model and the operation to refine never reached it.express-rate-limit/express-rate-limit (express-rate-limit)
v8.6.1Compare Source
You can view the changelog here.
mozilla/pdf.js (pdfjs-dist)
v6.2.108Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.